PT-2026-48809 · Netty+1 · Netty+1

·

CVE-2026-48059

·

Published

2026-06-11

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.135.Final Netty versions prior to 4.2.15.Final
Description The HAProxy PROXY protocol v2 codec leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested PP2 TYPE SSL TLVs (type-length-value records) at depth two or greater. This occurs during the successful parse path where the underlying cumulation buffer, a pooled and potentially direct ByteBuf allocated by the channel, remains permanently pinned even after the HAProxyMessage is released and the decoder removes itself.
Recommendations Update to version 4.1.135.Final. Update to version 4.2.15.Final.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BK55944
CLEANSTART-2026-KL03760
CLEANSTART-2026-NE94194
CLEANSTART-2026-YY96069
CVE-2026-48059
GHSA-H2QV-FJ59-J46J
OPENSUSE-SU-2026:11033-1
RHSA-2026:53644
SUSE-SU-2026:2802-1

Affected Products

Netty
Red Os